CVE-2026-20357Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Mentions · 2026-08-24: 2Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-24: 208-1908-2008-2408-28
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-201
General1
2026-08-242
Disclosure2
2026-08-281
Disclosure1
Full discourse5 posts
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na několik zranitelností v Cisco Crosswork, CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359. V produktech Cisco Crosswork Data Gateway, Crosswork Network Controller a Crosswork Planning byly identifikovány čtyři kritické zranitelnosti, které se projevují bez ohledu na konfiguraci zařízení. Jedná se o SQL Injection (CVE-2026-20030, CVSS 10.0), chybějící autentizaci pro kritickou funkci (CVE-2026-20357, CVSS 10.0), možnost externí kontroly souborového systému (CVE-2026-20358, CVSS 10.0) a nedostatečně chráněné přihlašovací údaje (CVE-2026-20359, CVSS 9.9). Úspěšné zneužití může útočníkovi umožnit neoprávněný přístup ke kritickým funkcím systému, manipulaci s daty, přístup k souborovému systému, kompromitaci přihlašovacích údajů a potenciálně úplné ovládnutí postiženého prostředí. Zranitelnosti ovlivňují Cisco Crosswork Release 7.2.1 a starší verze. 📌Doporučujeme aktualizovat na verzi 7.2.1-SP.

    Post summary

    The post announces four critical vulnerabilities in Cisco Crosswork with technical details and recommends updating to version 7.2.1-SP as mitigation.

    11010850
    4.3K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🔓 CVE-2026-20357 in Cisco Crosswork scores CVSS 10. No auth, no interaction, full C/I/A compromise with scope change over the network. About as bad as it gets. #cisco #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-20357?utm_campaign=x https://t.co/KBU4Tiq683

    Post summary

    The tweet announces CVE‑2026‑20357 in Cisco Crosswork, emphasizing its critical CVSS 10 score and total compromise potential, but offers no PoC, exploit, or patch information.

    01010242
    882 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🛡️ Cisco Crosswork and WordPress: Unexpected Critical Additions Cisco disclosed two perfect-10 vulnerabilities in its Crosswork network automation platform — CVE-2026-20357 and CVE-2026-20030 — as part of a proactive security hardening…

    Post summary

    The statement announces two perfect‑10 CVEs in Cisco Crosswork as part of proactive hardening, without detailing exploitation or mitigation.

    1000081
    80 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-20030 CVE-2026-20315 CVE-2026-20317 CVE-2026-20357 CVE-2026-20358 ..🧵👇

    Post summary

    The memo lists several CVE identifiers with no additional context, remediation, or exploitation details.

    1000033
    37 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-20357 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team h… CVSS 10.0 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-20357 #Cisco #CyberSecurity #InfoSec

    Post summary

    Cisco announces the critical CVE-2026-20357 with a CVSS score of 10.0 and indicates that no patch is available yet; a detailed analysis is linked for further information.

    0000038
    82 followersView on X

Explore more